CVE-2024-37889

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/06/2024
Last modified:
08/08/2024

Description

MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial information from another account. The vulnerability is fixed in 0.4.6.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:treyww:myfinances:*:*:*:*:*:*:*:* 0.4.6 (excluding)